AI governance is the system of rules, roles and controls an organisation uses to make sure its artificial intelligence is safe, legal, fair and accountable. It answers three questions that boards cannot afford to leave open: where is AI being used, who is responsible for each use, and how do we know it is behaving as intended. Governance is not a document you write once. It is an operating discipline that runs for as long as the systems do.
The framework itself is usually built from a policy that states principles and acceptable use, a register of every AI system in play, a consistent way to assess and grade risk, and the technical and human controls that keep higher-risk uses in check. In the UK this sits alongside established obligations, particularly data protection under UK GDPR, rather than replacing them. Good AI governance makes existing duties easier to meet, not harder.
Crucially, governance assigns responsibility to people, not to the technology. A model cannot be held to account, so accountability has to rest with named individuals, from the board that sets the risk appetite to the employee who checks an output before acting on it. The Institute of AI, the UK's professional body for AI, exists to define that standard and help organisations meet it. The sections below break the framework into its parts and set out who owns what.